PT-2025-25174 · K7 · K7 Security Anti-Malware Suite

Carlos Garrido

·

Published

2025-06-10

·

Updated

2025-09-17

·

CVE-2025-1055

CVSS v3.1

5.6

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions K7 Security Anti-Malware suite (affected versions not specified)
Description A flaw in the K7RKScan.sys driver allows a local low-privilege user to send crafted IOCTL requests to terminate a wide range of processes running with administrative or system-level privileges. This issue stems from missing access control in the driver's IOCTL handler, enabling unprivileged users to perform privileged actions in kernel space. Successful exploitation can lead to denial of service by disrupting critical services or privileged applications.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

LPE

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-1055

Affected Products

K7 Security Anti-Malware Suite